Crypto protocols that completed independent security audits accounted for 88.44% of all funds stolen since January 2025, according to CoinGecko’s 2026 state of crypto security report.
The study tracked 245 incidents and $3.63 billion in losses through July 2026. Independent auditors had cleared 147 of the breached platforms before attackers reached them.
CoinGecko said that only 11% of exploits involved in-scope smart contract flaws, though those cases still drained $396 million.
Follow us on X to get the latest news as it happens
The damage came from everywhere else. Attackers went after external infrastructure, code shipped after the audit closed, and systemic features that could be manipulated through governance.
Supply chain and infrastructure breaches took more than $1.8 billion, the largest single category in the report. Overall, smart contract exploit-driven losses across decentralized applications (dApps) reached $546 million.
May’s Stake DAO breach showed the limit. An attacker compromised a deployer key rather than exploiting contract logic. On centralized exchanges, stolen private keys remained the most common point of failure.
“Infrastructure and supply chain vulnerabilities have proven to be the most devastating for both CEXes and DEXes,” the report read.
The losses also cluster tightly. The 10 largest attacks alone produced 72.5% of everything taken across the 19-month window.
Cover against those losses is thinning too. Active on-chain insurance fell 20.2% to $130.2 million, and five of nine insurance protocols went inactive or changed direction.
Meanwhile, DefiLlama has logged 233 separate incidents so far in 2026, worth roughly $1.31 billion. The same stretch of 2025 saw 92 incidents and $2.37 billion in losses.
Incident volume more than doubled while total losses fell about 45%. Average loss per incident dropped from $25.8 million to $5.6 million. The $1.5 billion Bybit theft inflated the 2025 total.
Three cases carried most of this year’s total. Kelp DAO lost $292 million, and Drift Protocol lost $285 million in April 2026. These two also rank among the top three hacks since 2025, following Bybit
Smaller attacks now arrive pretty frequently, adding to the long list of 2026 crypto breaches. August alone brought an $8.5 million Term Labs governance exploit.
Overall, the pattern raises a scoping question rather than a competence one. Contract reviews remain narrow while deployment keys and governance parameters carry growing value.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights